RaCKDet: An Ensemble Learning Method for Network Intrusion Detection
Zijian Wang, Jiakun Sun · 2024
Network intrusion detection aims to identify malicious behaviors within network traffic, which is essential for cybersecurity. With the advancement of network technologies, the scope of network intrusions is expanding rapidly. Traditional signature-based network intrusion detection methods become ineffective, which face challenges in adapting to the evolving landscape of cyber threats. In recent years, both machine learning-based and deep learning-based methods have gained significant popularity. But these methods still struggle to perform optimally in real-world environments, and lack of interpretability, which can be a critical drawback when understanding and explaining their decision-making processes is required. We propose RaCKDet, an ensemble learning method for network intrusion detection. In detail, RaCKDet leverages the strengths of diverse detection methods by integrating Random Forest (RF), K-Means, and one dimensional Convolutional Neural Network (1D-CNN). Each of the base classifier independently generates a prediction for a given sample, and the final detection result is determined through a voting mechanism. The experiments show that RaCKDet outperforms baseline models while base models perform similar. Furthermore, we conduct ablation study and an analysis of network traffic features to elucidate the interpretive nature of RaCKDet, thereby compensating for the interpretability deficiencies often associated with deep learning methodologies.